Privacy Policy
Last updated: 3 September 2026
This policy explains what NovelKnow ("we", "us") collects when you use novelknow.com, why we collect it, and what control you have over it.
The short version
- Your manuscripts belong to you. We do not sell them, publish them, or use them to train AI models.
- We collect the minimum needed to run an account: an email address, and whatever you choose to put in your projects.
- When you use AI features, the text needed for that request is sent to the AI provider you have configured. That provider's own privacy policy then applies to that request.
- You can delete your account and its content at any time.
What we collect
Account information. Your email address, and optionally a display name and avatar. If you sign in with a password, we store a bcrypt hash of it — never the password itself. If you sign in through a third-party provider, we store the account identifier and tokens that provider issues so we can keep you signed in.
Content you create. Projects, books, chapters, scenes, codex entries, notes, prompts and settings. This is stored so we can show it back to you.
AI provider credentials. If you supply your own API key for an AI provider, it is encrypted at rest (AES-GCM) before being stored. It is decrypted only to make requests you initiate.
Billing information. If you subscribe to a paid plan, payment is processed by Stripe. We store the Stripe customer and subscription identifiers and your plan status. We never see or store your full card number.
Operational records. Usage counts, sign-in timestamps, and standard server logs, which we use to run the service and investigate abuse.
What we do with it
We use this data to provide the service, authenticate you, process subscriptions, and keep the service secure and working. We do not sell personal data, and we do not use your manuscripts to train models.
AI processing
NovelKnow sends text to AI providers only when you trigger an AI action. What is sent is the context required for that request — which may include excerpts of your manuscript, codex entries, and your prompt.
If you configure your own API key, the request goes to that provider under your own account and their terms and privacy policy govern it. We recommend reviewing the policy of any provider you connect. If you use a hosted plan where we supply the model access, the same principle applies to the provider we route through.
Where data is stored
Service data is stored in a managed database hosted in the United States. Traffic to the site is served over HTTPS.
Sharing
We share data only with providers that are necessary to operate the service: our hosting and database provider, Stripe for payments, our email delivery provider, Google Analytics for public-page traffic measurement (see Cookies and analytics below), and any AI provider you choose to use. We may also disclose data where we are legally required to.
Your manuscripts go to none of them except the AI provider you configure, and only for the request you asked for.
Retention and deletion
We keep your account data while your account exists. When you delete your account, the associated projects and content are deleted from the live database. Backups may retain copies for a limited period before they cycle out.
Your choices
You can access and edit your content in the app at any time, export your projects, correct your account details, or delete your account. If you are in a jurisdiction that grants you additional rights over your personal data — such as access, portability, correction, or erasure — you can exercise them by contacting us.
Cookies and analytics
We use cookies that are necessary for the service to work, principally to keep you signed in. We do not use advertising cookies, and we do not run advertising.
We also use Google Analytics to understand how people find our public pages — which articles bring writers to us, and which landing pages actually help. This is limited in two deliberate ways:
- It runs only on our public pages. The writing workspace, your settings, and every page that requires signing in are excluded entirely. Your project and scene identifiers are never sent to Google.
- Analytics cookies are off until you accept them. We ask on your first visit, and you can decline. Declining does not restrict any part of the service.
Google acts as our processor for this data. See Google's privacy policy for how they handle it.
Children
NovelKnow is not directed at children under 13, and we do not knowingly collect data from them.
Changes
If we change this policy materially, we will update the date above and, where the change is significant, notify account holders.
Contact
Questions about this policy: [email protected]